Threat Actors Exploit a Critical Ivanti RCE Bug, Again
ID: 95c6f77b-c5bd-5714-91b9-4edd9f92321e
STIX ID: report--95c6f77b-c5bd-5714-91b9-4edd9f92321e
Feed Name: Dark Reading
A suspected Chinese-linked APT (UNC5337) is actively exploiting a critical unauthenticated RCE (CVE-2025-0282, CVSS 9.0) in Ivanti Connect Secure and related gateways to deploy bespoke persistent malware (Spawn family) plus additional scripts (DryHook, PhaseJam); a second authenticated buffer overflow (CVE-2025-0283) was identified but not observed exploited. Ivanti and CISA have issued mitigations and patches; defenders are urged to run Ivanti’s Integrity Checker Tool and patch immediately to detect and remediate compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
